Answer in brief
CVE-2025-13590 records a Critical severity (CVSS 9.1) vulnerability in Authenticated arbitrary file upload via a System REST API requiring administrator permission.. The current sources do not mark it as known exploited. The current feed maps WSO2/org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl (generic), WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Traffic Manager (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl (generic), WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Traffic Manager (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.implgeneric | >=9.28.116 <9.28.116.391 || >=9.29.120 <9.29.120.210 || >=9.30.67 <9.30.67.133 || >=9.31.86 <9.31.86.100 || >=9.32.147 <9.32.147.2 | 9.28.116.391, 9.29.120.210, 9.30.67.133, 9.31.86.100, 9.32.147.2 |
| WSO2/WSO2 API Control Planegeneric | >=4.5.0 <4.5.0.39 || >=4.6.0 <4.6.0.3 | 4.5.0.39, 4.6.0.3 |
| WSO2/WSO2 API Managergeneric | >=4.2.0 <4.2.0.179 || >=4.3.0 <4.3.0.91 || >=4.4.0 <4.4.0.55 || >=4.5.0 <4.5.0.38 || >=4.6.0 <4.6.0.3 | 4.2.0.179, 4.3.0.91, 4.4.0.55, 4.5.0.38, 4.6.0.3 |
| WSO2/WSO2 Traffic Managergeneric | >=4.5.0 <4.5.0.37 || >=4.6.0 <4.6.0.3 | 4.5.0.37, 4.6.0.3 |
| WSO2/WSO2 Universal Gatewaygeneric | >=4.5.0 <4.5.0.37 || >=4.6.0 <4.6.0.3 | 4.5.0.37, 4.6.0.3 |
| org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1maven | <9.32.167 | 9.32.167 |
Published upstream
Feb 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 23, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 14, 2026
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.
Quoted source text, attributed separately from HOL analysis.